T09 · Insecure Skill Coding Practices
- Location
SKILL.md:55- Finding
Mandatory Disclosure of Contract Source and Build Metadata to a Third-Party Verification API
- Content
View full analysis
\ --chain 10143 \ --show-standard-json-input > /tmp/standard-input.json cat out/.sol/.json | jq '.metadata' > /tmp/metadata.json COMPILER_VERSION=$(jq -r '.metadata | fromjson | .compiler.version' out/.sol/.json) # 2. Call verification API STANDARD_INPUT=$(cat /tmp/standard-input.json) FOUNDRY_METADATA=$(cat /tmp/metadata.json) cat > /tmp/verify.json << EOF { "chainId": 10143, "contractAddress": "0xYOUR_CONTRACT_ADDRESS", "contractName": "src/MyContract.sol:MyContract", "compilerVersion": "v${COMPILER_VERSION}", "standardJsonInput": $STANDARD_INPUT, "foundryMetadata": $FOUNDRY_METADATA } EOF curl -X POST https://agents.devnads.com/v1/verify \ -H "Content-Type: application/json" \ -d @/tmp/verify.json ``` ### Technical Analysis The Skill instructs the agent to submit the complete Solidity standard JSON compiler input and Foundry metadata to `agents.devnads.com`. Standard JSON input can contain the complete source tree, imported source files, compiler settings, and other project details. Foundry metadata can additionally disclose build and source-reference information. Although contract verification inherently involves publishing verification material, routing it through this third-party aggregation API is not the least-privileged option. The same Skill documents direct Sourcify verification as a fallback, demonstrating that disclosure to this intermediary is not technically mandatory. The workflow does not require user consent, show the exact payload before transmission, inspect source files for embedded credentials, or document the receiving service's retention and privacy properties. It also writes the complete payload t ...[truncated 1478 chars]- Remediation
View remediation
